CVE-2024-39937
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-39937 is a newly disclosed vulnerability affecting supOS 5.0. This issue permits attackers to perform directory traversal attacks through the api/image/download endpoint, enabling them to read sensitive files outside of the intended directory. By manipulating the fileName parameter, an adversary can access files that are located above the current working directory, posing a significant risk to system security. The vulnerability could potentially lead to data leakage or unauthorized access, underscoring the importance of applying available patches promptly.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- supOS
Affected Vendors
- Zhejiang Lanzhuo Industrial Internet Information Technology Co Ltd